TL;DR

  • Self-custody means the holder, and nobody else, controls the means of access to their assets: the keys, or every share of a distributed key arrangement needed to sign. The line is drawn by one question, asked of each party in the system: could they move the assets, or block the holder from moving them, without the holder's consent?
  • For bitcoin, the best-measured asset, roughly 65 percent of supply, over 800 billion dollars in value, sits in self-custody by River's 2025 estimate, with roughly 23 percent held with exchanges and direct custodians, a remainder derived from the two stated figures, and 11.6 percent through ETFs and treasury companies. For other assets no comparable estimate exists, and even the bitcoin figures are heuristics rather than a census.
  • Around one in ten American adults used or held crypto in 2025 by the Federal Reserve's survey, awareness in the UK stands at 91 percent of adults, and 73 percent of UK users acquire coins through centralised exchanges; how many holders control their own keys is a number no authoritative instrument currently measures. That gap is the largest open question in custody research, and this report exists partly to keep pointing at it.
  • The great push was 2022, when yield platforms and FTX failed and River's gross incident data associates more than 100,000 BTC with the collapses, customers losing access and becoming creditors, teaching the difference between an account balance and a key; the great pull is the ETF era, which offers exposure without responsibility and now accounts for roughly a ninth of bitcoin's supply. Both currents are real, they run concurrently, and they are reshaping who ends up in each model.
In one block

The State of Crypto Self-Custody is a periodically updated research report that measures how crypto holders custody their assets: the share of value held in holders' own keys versus exchanges, custodians and funds, the number of people involved, the events that move them between models, and the technology they use.

What counts as self-custody, and where is the line?

Quick answer

Self-custody means the holder, and nobody else, controls the means of access to their assets: the keys, or every share of a distributed key arrangement needed to sign. The line is drawn by one question, asked of each party in the system: could they move the assets, or block the holder from moving them, without the holder's consent?

The clean cases are easy. Coins on an exchange are custodial: the provider or its custodian controls the signing keys, and the customer's property or claim rights in an insolvency depend on the contract, the segregation arrangements and the applicable law, with some account types treated in recent proceedings as unsecured claims, a lesson 2022 taught at scale. A hardware wallet whose seed phrase exists only in the holder's safe is self-custody: full control, full responsibility, no counterparty. Between the poles sit arrangements that need the question asked precisely. In a multisignature quorum, custody follows the keys: a holder with all quorum keys is in self-custody, a holder sharing them with a service is in something shared. In MPC wallets, where key shares sign jointly and the complete key need never exist, the answer depends on the design: who holds which shares, whether the provider's share can sign without the holder, and whether the holder can reach a signing quorum, or recover one, if the provider disappears. Sound designs answer those questions in the holder's favour; the label alone guarantees nothing, and this report treats "MPC self-custody" as a claim to verify per implementation rather than a category that settles the matter.

Regulation in the EU draws a similar line. MiCA defines custody, in Article 3(1)(17), around safekeeping or controlling cryptoassets or the means of access to them, and Article 75 attaches duties to that activity, including segregation, which is why providers that never control a client's keys or a signing quorum sit differently from exchanges, and why the analysis is one of facts and circumstances rather than branding. The practical consequence for readers: whether an arrangement is self-custody is a technical question about who can sign, answerable from the design, and worth answering before value moves in.

How much crypto is actually in self-custody?

Quick answer

For bitcoin, the best-measured asset, roughly 65 percent of supply, over 800 billion dollars in value, sits in self-custody by River's 2025 estimate, with roughly 23 percent held with exchanges and direct custodians, a remainder derived from the two stated figures, and 11.6 percent through ETFs and treasury companies. For other assets no comparable estimate exists, and even the bitcoin figures are heuristics rather than a census.

The table collects the principal figures, each tagged with what it measures.

FigurePeriodWhat it measuresSource
~65% of BTC supply2025Estimated share of bitcoin in self-custodyRiver
Over 800 billion dollars2025Estimated value of self-custodied bitcoinRiver
~300 billion dollars (~11.6% of supply)2025Bitcoin held via ETFs and treasury companiesRiver
~35% of custodial BTC2025Exchanges' share of third-party-held bitcoin, down from over 50% in 2021River
~30 million2025Americans holding bitcoin on exchanges or with custodiansRiver
~50 million2025Americans with indirect bitcoin exposureRiver
>12 million BTC2025Bitcoin unmoved for a year or moreRiver
>6 million BTC2025Bitcoin unmoved for five years or moreRiver
Figure from The State of Crypto Self-Custody 2026
Figure 1. How bitcoin is held, by approximate share of supply in 2025. Self-custody remains the majority arrangement; the third-party share is derived as the remainder of the two stated figures.

Three readings of the table repay attention. First, the headline: self-custody is the majority arrangement for bitcoin, by value, and by a wide margin. The popular narrative in which ordinary holders have surrendered custody wholesale to platforms is a story the data declines to support. Second, the composition of the custodial minority is professionalising: within third-party custody, exchanges' share fell from over half in 2021 to roughly 35 percent, with regulated institutional custodians taking the majority, a shift the exchange failures of 2022 did much to force. Third, the fastest-growing channel is one where custody questions are invisible to the end holder: an ETF investor owns a securities claim, a custodian holds the coins, and the holder may never form a view about keys at all.

The caveats are structural. These are estimates built on address clustering, disclosed holdings and on-chain heuristics; they describe bitcoin, and no equivalent authority exists for the long tail of other assets; and dormancy, which the last two rows measure, cannot distinguish deep cold storage from lost keys, a limitation River states plainly and this report repeats wherever the figures appear.

How many people hold crypto, and how many hold their own keys?

Quick answer

Around one in ten American adults used or held crypto in 2025 by the Federal Reserve's survey, awareness in the UK stands at 91 percent of adults, and 73 percent of UK users acquire coins through centralised exchanges; how many holders control their own keys is a number no authoritative instrument currently measures. That gap is the largest open question in custody research, and this report exists partly to keep pointing at it.

The population data comes from instruments with different strengths. The US Federal Reserve's Survey of Household Economics and Decisionmaking, the most rigorous national series, found 10 percent of US adults used or held cryptocurrency in 2025: 9 percent as an investment, 2 percent for transactions, with the transactional share concentrated among the unbanked, of whom 6 percent used crypto to transact. The series peaked at 12 percent in 2021, fell to 7 percent in 2023, and has recovered for two consecutive years. The FCA's 2025 consumer research, fielded through YouGov in August and September 2025 with over three thousand interviews, found 91 percent of UK adults aware of cryptoassets, and among UK users, 73 percent acquiring coins through centralised exchanges, up four points in a year; 25 percent of users said they would invest more under a clearer UK regulatory regime. Chainalysis's 2025 Global Adoption Index, which measures activity rather than people, ranked India first and the United States second, with Asia-Pacific the fastest-growing region at 69 percent year-on-year growth and more than 1.2 trillion dollars in gross bitcoin purchases through fiat pairs on tracked centralised exchanges between July 2024 and June 2025.

Figure from The State of Crypto Self-Custody 2026
Figure 2. What the surveys measure, and where they stop. Each row is a different instrument and jurisdiction; no authoritative measure of key-holding exists.

Now the gap. Ownership surveys stop at "do you own crypto" and rarely ask where the keys are; the FCA's research measures how users buy, which says little about where assets end up; on-chain analysis sees addresses and can estimate value shares, and cannot count the people behind them. Put the two instrument families side by side and the missing middle is obvious: we know roughly how many people hold crypto in the surveyed jurisdictions, and roughly what share of bitcoin's value sits in self-custody, and almost nothing rigorous about how many people those keys belong to, what they believe about their arrangements, or how many could actually recover their assets tomorrow. Value shares and headcounts also diverge by construction, since self-custodied value is concentrated among long-term and large holders while the widest populations touch crypto through exchanges and funds. Future editions of this report are planned to address the perception side directly with dedicated survey data; the methodology will be published alongside the results, and until then this report declines to invent the number.

What pushed holders toward self-custody, and what pulls them away?

Quick answer

The great push was 2022, when yield platforms and FTX failed and River's gross incident data associates more than 100,000 BTC with the collapses, customers losing access and becoming creditors, teaching the difference between an account balance and a key; the great pull is the ETF era, which offers exposure without responsibility and now accounts for roughly a ninth of bitcoin's supply. Both currents are real, they run concurrently, and they are reshaping who ends up in each model.

The push has dates and numbers. Through 2022, the yield-bearing platforms, Celsius, Voyager, BlockFi among them, and then FTX in November, failed with customer assets inside; River's gross incident dataset associates more than 100,000 BTC, roughly 2 billion dollars at the time, with collapsed yield-bearing services in that year alone; customers lost access and became creditors, and the series does not net the partial recoveries some proceedings later paid. The phrase "not your keys, not your coins" stopped being a slogan and became a practical lesson of the proceedings, several of which treated particular account types as unsecured claims of the estate, with outcomes turning on contract terms, segregation arrangements and applicable law. The custody data shows the response: exchanges' share of custodial bitcoin fell from over half in 2021 to roughly 35 percent, and the survivors moved toward proof-of-reserves publication and segregation commitments, while institutional custodians, whose offerings are typically structured around segregation commitments that vary by licence and jurisdiction, took the larger share of what remained with third parties.

The pull is newer and better dressed. Since the US approved spot bitcoin ETFs in January 2024, intermediated exposure has grown into the fastest-expanding custody channel: roughly 300 billion dollars through ETFs and treasury companies by 2025, with as many as 50 million Americans holding indirect exposure by River's estimate, against roughly 30 million holding coins on exchanges or with custodians. The ETF investor gets familiar rails, brokerage statements and no key ceremony; they also get a claim rather than an asset, counterparty and structure risk in place of key risk, and no ability to withdraw coins. Chainalysis's index attributes much of North America's 49 percent activity growth to exactly this institutional and ETF demand. Neither current is a verdict. The push taught that intermediaries fail; the pull demonstrates that most new money still prefers intermediaries when they come with regulation and familiar interfaces. A mature reading is that the population is sorting by temperament and stake: direct holders with high conviction concentrate value in self-custody, broad shallow adoption arrives intermediated, and the interesting question for the next five years is which way the middle moves as self-custody tooling gets easier and regulated custody gets cheaper.

Figure from The State of Crypto Self-Custody 2026
Figure 3. The two currents moving custody in opposite directions: the post-2022 flight from failed platforms, and the ETF era's pull toward intermediated exposure. The 100,000 BTC figure is gross and does not net later recoveries.

What does self-custody cost its users?

Quick answer

Responsibility, permanently: River uses dormancy heuristics to estimate roughly 1.57 million BTC as permanently lost, with 98 percent of its estimated losses occurring before 2020, while stating it cannot determine how much was lost through self-custody specifically and considering it reasonable only that most sat outside custodial platforms. The honest comparison is between two risk profiles, self-custody's operational risk against custody's counterparty risk, rather than between danger and safety.

The loss ledger, from River's research: over 3 million BTC estimated lost or stolen across bitcoin's history, of which River's dormancy heuristics place roughly 1.57 million as permanently lost, with 98 percent of the estimated losses occurring before 2020. River states it cannot determine how much of that was lost through self-custody specifically, considering it reasonable only that most sat outside custodial platforms, and the estimate does not by itself prove that modern tooling reduced the loss rate, since dormancy cannot prove loss and newer coins have had less time to satisfy any dormancy rule. Against it, the custodial ledger: more than 100,000 BTC associated in gross terms with the failed yield platforms of 2022, recoveries not netted, roughly 2.6 billion dollars to embezzlement at intermediaries since 2020, and the older exchange-failure record stretching back through Mt. Gox. QuadrigaCX remains the governance cautionary tale: Ontario's securities regulator concluded the platform ran as a fraud, with client money lost to trading rather than to any custody accident. Loss, in other words, is a property of every custody model; what differs is the failure mode, operational error in one, counterparty behaviour in the other. All these figures carry their instruments' limits: dormancy cannot prove loss or identify the custody arrangement behind it, documented losses are floors, and neither ledger supports ranking the models' lifetime risk for a given holder, which depends overwhelmingly on that holder's practices.

The ledger gained a fresh entry as this edition closed, and it complicates any comfortable reading of the loss record as ancient history. On 30 July 2026, Coldcard's maker disclosed a seed-generation flaw in firmware descended from a March 2021 build. Affected generations were not equally exposed: Coinkite preliminarily estimated an effective search space of roughly 40 bits for affected Mk2 and Mk3 seeds and roughly 72 bits for affected Mk4, Q and Mk5 seeds, while independent analysis by Block found no cryptographic entropy entering the vulnerable Mk2/Mk3 generation path and only a 32-bit secure-element reseed on later models, cautioning that timer-inclusive search-space ceilings are not equivalent to cryptographic security. Practical exploitability depended on device state, timing and RNG call history, and the estimates remained preliminary while the investigation continued; the sweeps that followed showed the space was, in practice, searchable. Sweeps of vulnerable wallets followed in waves; Galaxy Research, as reported by CoinDesk, attributed 1,367 BTC, approximately 88 million dollars at the early-August cut-off, taken across about 4,585 addresses, to three waves, and separately flagged a suspected fourth wave of roughly 449 BTC that would raise the estimate toward 114 million dollars, an attribution resting on pattern matching with no victim yet confirmed when this edition closed. Fixed firmware shipped on 1 August 2026, with users directed to generate fresh seeds and migrate, since new firmware cannot repair a key that was already born weak. Independent forensic work sharpened the picture. Security researcher Vladimir S., writing as Officer's Notes, documented an initial sweep of roughly 1,195 addresses in about 41 minutes and two concurrent waves whose proceeds consolidated in the same block, in the same minute, pointing to a single actor rather than competing attackers; Chainalysis observed that high-value wallets were hit early, suggesting the attacker had studied the victim population before moving. Two details matter for this report's argument. Officer's Notes reported that the addresses in its examined set were single-signature. And seeds created with fifty or more user-supplied dice rolls, or protected by long unique BIP39 passphrases, sat outside the vulnerable set, because user-added entropy and a second secret both survived the firmware's failure. Tallies differ between trackers and cut-off times, so per this report's method each is quoted with its instrument rather than merged. The structural lesson for this report is precise: self-custody's operational risk includes the implementation quality of the tools themselves, an exposure no amount of user discipline detects from the outside, and one that argues for designs in which no single device's randomness, or any other single component, can be fatal on its own. All figures here are as of early August 2026 and will be revised in the next quarterly pass.

Two costs are not in the ledgers. The first is the burden itself: key management, backup discipline, inheritance design and signature hygiene are real work, the failure modes are unforgiving, and the loss report in this academy documents how they bite. The second arrived with crypto's prosperity: a holder known to control their own keys can be coerced, and CertiK documented a record 72 physical attacks on holders in 2025. Both costs are addressable, by better tooling, by custody designs without a single extractable secret, and by discretion, and both belong in any honest accounting of what holding your own keys asks of you. A practitioner literature has grown around the coercion problem, and security researcher Vladimir S., writing as Officer's Notes, catalogues its range: duress PINs that open a small decoy wallet while alerting or wiping, prearranged code words that silently signal trusted contacts, time-locked quorums that make forced transfers slow and visible, and, at the experimental fringe, steganographic and physical concealment methods, with the sober caveat that obscurity layers supplement sound custody architecture and never replace it.

How is the technology of self-custody changing?

Quick answer

Through four generations aimed at the same enemy: from single keys with paper seed phrases, to hardware isolation, to multisignature quorums, to MPC threshold signing, each removing a single point of failure the previous generation left standing. None removes the need for sound recovery design, independent signers and verified implementations, and each trades convenience differently.

The first generation gave one device the complete key and one sentence, the seed phrase, the power to restore it: simple, sovereign and brittle, with one object to steal and one to lose. Hardware wallets, the second generation, moved the key off internet-connected devices into dedicated signing hardware, a genuine advance against malware that left the seed phrase itself as the single point of failure; the academy's seed phrase article walks that anatomy. The 2026 Coldcard entropy flaw added the generation's asterisk: isolation protects a key only as well as the vendor's code generated it, so implementation quality and independent review belong in any hardware evaluation. Multisignature, the third, put a quorum of independent keys between assets and any single failure; legacy and script-path setups can reveal the policy on-chain, while Taproot key-path aggregated signatures need not, and the mechanics differ per chain. The fourth generation, MPC threshold signing, specified in schemes such as FROST, moves the quorum inside the cryptography: key shares held by different parties sign jointly without the complete key being assembled at use, and in designs that use distributed key generation the complete key need never exist at all. Institutions adopted MPC first, for operational reasons the institutional custody article covers, and consumer MPC wallets have since brought the same structure to individuals, sometimes paired with guardian-based or quorum recovery designs that replace the seed phrase entirely.

Figure from The State of Crypto Self-Custody 2026
Figure 4. Four generations of self-custody technology, each attacking the single point of failure the previous one left standing.

The through-line matters more than any generation's marketing. Each step attacks the single point of failure, the structural feature this academy's loss research finds behind most catastrophic outcomes in every custody model. And each step's claims are conditional: a multisig whose keys share a backup is a single point of failure in costume, and an MPC wallet's guarantees depend on who holds which shares, how they were generated, and what the recovery and administrative paths allow. The evaluation discipline is the same across generations, and the academy's comparison articles apply it: ask what one stolen component yields an attacker, what one lost component costs the holder, and who, if anyone, can act without you.

Where is self-custody heading by 2027?

Quick answer

Toward coexistence and sharper boundaries: regulated intermediated exposure keeps absorbing broad new demand, self-custody keeps deepening among direct holders as tooling matures, and the developed regulatory regimes increasingly reason about custody from control of assets or their means of access, at different speeds in different jurisdictions. The report will re-measure rather than predict.

Three developments look durable enough to state. First, the regulatory picture is developing jurisdiction by jurisdiction rather than converging on one rule. The EU's MiCA defines custody around safekeeping or control of assets or their means of access and attaches duties to it; the UK's new cryptoasset regime is scheduled to commence in October 2027; and the United States remains a fragmented patchwork of federal and state frameworks. What the developed regimes share is a tendency to reason from control, which will keep sorting products by their actual signing architecture rather than their branding. Second, the intermediated channel will keep growing in absolute terms as long as ETF-style access exists, and its holders will keep needing education about exactly what they hold, a claim, and what they do not, coins. Third, self-custody's operational cost appears to be falling: the maturing of hardware, quorum and MPC designs and the growth of recovery architectures without single secrets all point that way, and the before-2020 concentration of River's estimated losses is consistent with it, though a dormancy estimate cannot by itself prove a modern loss rate, and the 2026 Coldcard flaw is the standing reminder that vendor implementation risk does not fall with user skill. What this report will refuse to do is forecast shares. The 2022 push was unforecast, the ETF pull's scale surprised its own sponsors, and custody flows follow events. The commitment instead is measurement: the figures above will be re-verified quarterly, the survey gap this report identifies is on its roadmap, and readers citing the report should quote each number with its instrument and date.

Frequently asked questions

Is most crypto held on exchanges?

For bitcoin, no. River's 2025 research estimates roughly 65 percent of supply in self-custody, and within the third-party remainder, exchanges' share has fallen from over half in 2021 to roughly 35 percent as institutional custodians grew. No comparable estimate exists for most other assets, and holdings patterns differ by asset and holder type.

How many people keep their own keys?

Nobody authoritatively knows, and this report treats that as a finding. Surveys measure ownership and buying channels; on-chain analysis measures value and addresses; neither counts key-holders. The figure most often wanted, what share of holders could actually recover their assets unaided, has no rigorous public measurement, which is the gap future survey editions of this report aim to address.

Is self-custody more dangerous than leaving coins on a platform?

They carry different risks rather than more and less of one risk. Self-custody's losses are operational, lost keys, failed backups and, as 2026's Coldcard incident showed, flaws in the tools themselves; River's dormancy-based estimate concentrates 98 percent of estimated losses before 2020, while stating it cannot attribute the losses to self-custody specifically. Custodial losses are counterparty events, insolvency, misuse and fraud, and 2022 wrote the largest recent entries. Which risk dominates for a given holder depends on their practices, their stake and their alternatives, which is why this academy's guides treat the choice as a design decision rather than a verdict.

Do ETF investors hold bitcoin?

They hold regulated exposure to bitcoin's price: a securities claim on a fund whose custodian holds the coins. That serves many investors well, and it differs from holding the asset: an ETF position cannot be withdrawn as coins, transacted on-chain, or held without the fund structure. The distinction is worth understanding before choosing either route, and as many as 50 million Americans may sit on the exposure side of it by River's estimate.

What is MPC self-custody, and is it really self-custody?

MPC wallets split signing power into shares that cooperate to sign without assembling the complete key, and with distributed key generation no complete key need ever exist. Whether a given MPC wallet is self-custody is a facts-and-circumstances question: it depends on who holds which shares, whether any party can sign or block signing without the holder, and whether the holder can recover a quorum independently. Sound designs answer those questions in the holder's favour and publish enough detail to verify; the label alone settles nothing.

Sources and further reading

Primary sources for this edition, current as of August 2026. Figures are re-verified each quarter, and changes are noted in revision history.

To cite this report: Bron Academy, The State of Crypto Self-Custody 2026, first edition, August 2026, bron.org/academy.

Quick quiz: did it stick?

A few questions to check the fundamentals landed. Answers with explanations follow, and nobody is grading you except your future portfolio.

1/7 question
Roughly what share of bitcoin's supply does River's 2025 research estimate is held in self-custody?

Was this helpful?